phpÈçºÎÅжÏÊäÈëµÄÊÇÊý×Ö£¬´úÂëÈçºÎд°¡
is_numeric
if (is_numeric($_POST["product_id$i"])) {
echo " <script>alert('error!'); </script>";
exit;
}
²»¶Ô°¡ ÓдíÂð
PHP code:
if(preg_match("/^\d*$/",$num)){
}
ÊÇÊý× ......
1.¾«Í¨ÃæÏò¶ÔÏóµÄÉè¼ÆºÍ¿ª·¢£»
2.ÊìÁ·Ê¹ÓÃPHPÓïÑÔ(5.0+)½øÐÐÊý¾Ý¿â£¬ÍøÂçͨÐÅ£¬Îļþ¶Áд£¬°²È«»úÖÆµÈ¿ª·¢£»
3.ÊìÁ·Ê¹ÓÃMYSQL(5.0+)Êý¾Ý¿â¿ª·¢£¬°üÀ¨»ù±¾µÄÊý¾Ý¿âÉè¼Æ/ÓÅ»¯/°²È«£¬¸´ÔÓµÄT-SQLÓï¾ä±àд£¬ÊìÁ·±àдMYSQL´æ´¢¹ý³Ì£»
4.ÊìÁ·Ê¹ÓÃZF¿ª·¢¿ò¼Ü£¬ÓÈÆäÒªÊìϤ³£ÓÃÆä×é¼þ£¬ÈçDB,SESSION,AUTH,MAIL,CACHE,RESTµÈ£»
5.¾ ......
֮ǰÓÐÓÃdelphi×öÁËÒ»Ì×£¬µ«ÊÇÏÖÔÚ¿ÍÈËÏë×ö³ÉB/S¼Ü¹¹µÄ£¬ÓÉÓÚÊǸոսӴ¥PHP£¬ËùÒÔ²»ÖªµÀPHPÊÇ·ñÄÜʤÈΣ¿
phpÒ»µãÎÊÌâҲûÓУ¬¿Ï¶¨ÄÜʤÈÎ
沒問題£¬Èç¹ûÓÐ問題¾ÍÊÇÒò為樓Ö÷結ÌûÂʱÈ較µÍ°É
phpÒ»µãÎÊÌâҲûÓУ¬¿Ï¶¨ÄÜʤÈÎ
phpÔÚ¹úÍâºÜÁ÷Ðеģ¬ÓÐǰ;Ŷ£¬¿ÉÒÔ ......
Óиö¼òµ¥µÄ×Ö·û´®´¦Àí£¬³õѧ£¬Âé·³°ïæÏ£º
´úÂ룺
while£¨ $rs = @mysql_fetch_array($query) £©
{
$i = 'a' ;
¡¡
(1) ;
}
(1)λÖõĴúÂëÔõôд£¬ÎÒ²ÅÄÜʹµÚÒ»´ÎÑ»·ºÃÒÔºó£¬$i±ä³É"aa" , µÚ¶þ´ÎÑ»·ºÃÒÔº ......
<!--¹ºÂòÊýÁ¿-->
<div class='buyinfo'>
<table width='auto'>
<tr>
<td><span>¹ºÂòÊýÁ¿£º</span></td>
<td> <div class="Numinput">
......
´ó¼ÒºÃ£¬
ÎÒÏëÓÃphpʵÏÖÒ»¸öÊ÷Ðνṹͼ£¬ÏÖÔÚ²»ÖªµÀÈçºÎʵÏÖ¡£
Ï£ÍûÄÜÌýµ½´ó¼ÒµÄÏë·¨ºÍ˼·¡£Èç¹ûÄܸ½ÉÏʾÀý´úÂë»òÔ´Âë¾Í¸üºÃÁË£¡£¡
Ìáǰ¸ÐлÀ²¡£
Óöþ²æÊ÷À´±íʾÊ÷£¬ÏÈÉú³ÉºóÏÔʾ
ÏÔʾµÄʱºòÓÃgd¿â»Í¼
ÒýÓÃ
Óöþ²æÊ÷À´±íʾÊ÷£¬ÏÈÉú³ÉºóÏÔʾ
лл£¬²»¹ýÎÒÕâÊǵÚÒ»´Î×ö ......